Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

ZuckerBot — Meta Ads MCP Server

NPM · ZUCKERBOT-MCP · 2 COMPONENTS · SCANNED AUG 3

60+ Meta Ads tools for AI agents: audits, campaign management, audiences and CAPI tracking.

+58 this week 64 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security83
  • No malware found by supply-chain analysis.Pass
  • CVE check failed: a known medium-severity CVE affects @hono/node-server 1.19.17, reached via @modelcontextprotocol/sdk > @hono/node-server. A fixed version is available. View diagnostics → Fail
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (113 of 117), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency45
Schema Quality & AI Usability56
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 9145 tokens (~152/item across 60 items; 60 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · zuckerbot-mcp

# add to Claude Code
claude mcp add crumbedsausage-zuckerbot -- npx -y zuckerbot-mcp
# add to Codex CLI
codex mcp add crumbedsausage-zuckerbot -- npx -y zuckerbot-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "crumbedsausage-zuckerbot": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "zuckerbot-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add crumbedsausage-zuckerbot --command npx --arg -y --arg zuckerbot-mcp
# ~/.hermes/config.yaml
mcp_servers:
  crumbedsausage-zuckerbot:
    command: "npx"
    args: ["-y", "zuckerbot-mcp"]
// mcp.json
{
  "mcpServers": {
    "crumbedsausage-zuckerbot": {
      "command": "npx",
      "args": [
        "-y",
        "zuckerbot-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 −3

    No change was recorded against any check on this day. Supply Chain Security went from 93 to 83. Other categories moved too: Stability & Change Management rose 4.

  • 2 Aug 26 +25
    • Known CVEs: unverified → fail security
    • Malware scan: unverified → pass security
    • Dependency health: unverified → partial functional
  • 1 Aug 26 −9
    • Known CVEs: fail → unverified security
    • Dependency health: partial → unverified functional
  • 31 Jul 26 +45
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −40
    • Provenance: fail → unverified security
    • Known CVEs: fail → unverified security
    • Install scripts: pass → unverified security
    • GHSA-frvp-7c67-39w9 no longer affects this package security
    • Dependency health: partial → unverified functional
    • Maintenance: pass → unverified functional
    • Security disclosure: fail → unverified functional
    • Tool coverage: 100 → unverified functional
    • License: pass → unverified functional
    • Licence: MIT functional
  • 29 Jul 26 +20
    • GHSA-frvp-7c67-39w9 affects this package: medium security
    • Known CVEs: unverified → fail security
    • Provenance: unverified → fail security
    • Install scripts: unverified → pass security
    • License: unverified → pass functional
    • Dependency health: unverified → partial functional
    • Maintenance: unverified → pass functional
    • Licence: MIT functional
  • 28 Jul 26 +20
    • Tool coverage: unverified → 100 functional
    • First check of Schema quality: fail functional
    • First check of Tool coverage: 100 functional
    • First check of Schema quality: fail functional
    • First check of Schema quality: unverified functional
  • 27 Jul 26 6

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Analysed npm/[email protected]

Provenance none

Ecosystem: npm · Outcome: none

Vulnerabilities 1 finding
ID CVE Severity Vector Fix available
GHSA-frvp-7c67-39w9 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N yes
Dependencies 113 packages

113 packages in the resolved dependency tree · 112 deprecated · 34 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 60 exposed · ~9,145 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
zuckerbot_research_reviews ~126

Fetch review intelligence for a business by name. Searches Google and Yelp to surface star rating, review count, recurring sentiment themes, and standout customer quotes that can be used directly in ad copy. Use before creating a campaign to identify proof points and objection-handling angles.

NameTypeReqDescription
business_namestringyesBusiness name to research reviews for (e.g., 'Rosebud Dental Austin')
locationstringOptional city/region to narrow review search (e.g., 'Austin, TX')
platformstringReview platform to search. Defaults to all.

No output schema declared.

No examples provided.

zuckerbot_rotate_webhook_secret ~101

Rotate the Conversions API webhook secret for a business. The new secret is returned exactly once, in this response only — every other read shows just webhook_secret_set and webhook_secret_last4. The old secret stops authenticating immediately, so update the system that signs your inbound webhooks (for example your CRM workflow's stored secret) in the same sitting.

NameTypeReqDescription
business_idstringOptional business ID override for the authenticated API key

No output schema declared.

No examples provided.

zuckerbot_send_capi_event ~365

Manually send a Conversions API event for a business contact/lead. Useful for debugging CAPI pipelines, testing stage mappings with real user data, or sending events from custom integrations not covered by the webhook. Authenticates with the business API key OR with an x-zuckerbot-webhook-secret header if using the webhook path.

NameTypeReqDescription
business_idstringOptional business ID override (resolved from API key when omitted)
crm_sourcestringOptional CRM source label override (e.g., 'hubspot', 'salesforce')
emailstringOptional contact email for identity matching
event_timestringOptional ISO 8601 event timestamp. Defaults to now.
fbcstringOptional pre-formatted Facebook click cookie (fb.1.<ms>.<fbclid>), forwarded raw — never hashed
fbclidstringOptional Facebook click ID; the server builds a well-formed fbc cookie from it
fbpstringOptional Facebook browser ID cookie (_fbp), forwarded raw — never hashed. Improves match quality for every event
first_namestringOptional first name for identity matching
last_namestringOptional last name for identity matching
lead_idstringOptional ZuckerBot lead ID for attribution matching
meta_lead_idstringOptional Meta Lead Gen Ads lead ID for attribution matching
phonestringOptional contact phone for identity matching
source_stagestringyesCRM stage key to map to a Meta event (e.g., 'lead', 'salesqualifiedlead', 'customer')
valuenumberOptional event value override in major currency units

No output schema declared.

No examples provided.

zuckerbot_set_capi_config ~297

Update the Conversions API configuration for a business. Set stage-to-event mappings (e.g., 'lead' → Meta Lead event), enable/disable delivery, change the CRM source, currency, optimisation target, or action source. Changes take effect immediately for new CAPI events. Use zuckerbot_capi_test to verify the updated config works.

NameTypeReqDescription
action_sourcestringMeta Conversions API action_source. Defaults to website for CRM events
business_idstringOptional business ID override for the authenticated API key
crm_sourcestringCRM source label, such as hubspot
currencystringBusiness currency used for CAPI event values, such as USD or AUD
event_mappingobjectCRM stage mapping object keyed by source stage. Stage keys are normalised (lower-cased, non-alphanumerics stripped: signup_completed → signupcompleted); inbound webhook source_stage values are normal…
is_enabledbooleanEnable or disable CAPI delivery for the business
optimise_forstringDownstream optimisation target for autonomous evaluation
rotate_webhook_secretbooleanRotate the webhook secret on update. The new secret is returned exactly once in the response; prefer zuckerbot_rotate_webhook_secret for a dedicated rotation

No output schema declared.

No examples provided.

zuckerbot_suggest_angles ~65

Return only the creative angles and audience tiers for a campaign draft — a lightweight alternative to zuckerbot_get_campaign when you need just the strategy summary without the full campaign payload, stored creatives, or tier execution details.

NameTypeReqDescription
campaign_idstringyesCampaign ID

No output schema declared.

No examples provided.

zuckerbot_sync_conversion ~238

Send downstream conversion quality feedback to Meta via CAPI. When a ZuckerBot-sourced lead converts (sale, appointment, qualified call) or bounces (uncontactable, bad fit), reporting it here teaches Meta's algorithm to find more (or fewer) people like them — improving lead quality over time. Call this from your CRM when a lead status changes.

NameTypeReqDescription
campaign_idstringyesZuckerBot campaign ID
fbcstringOptional pre-formatted fbc cookie, forwarded raw — never hashed
fbclidstringOptional Facebook click ID; the server builds a well-formed fbc cookie from it
fbpstringOptional _fbp browser cookie, forwarded raw — never hashed. Improves match quality
lead_idstringyesLead ID to report conversion for
meta_access_tokenstringyesUser's Meta access token for CAPI
qualitystringyesLead quality: 'good' = converted/contacted, 'bad' = lost/unresponsive
user_dataobjectOptional user data to improve match rate

No output schema declared.

No examples provided.

zuckerbot_tag_creative ~114

Tag Meta ads with creative attributes (hook type, visual style, product focus, CTA type, copy tone, setting) by providing ad metadata and optional asset URLs. ZuckerBot uses Claude vision to analyze the creative and store structured tags. These tags feed the zuckerbot_creative_analysis pipeline. Run this after launching new ads to keep the creative intelligence database current.

NameTypeReqDescription
adsarrayyesOne or more Meta ads to tag with creative attributes
business_idstringOptional business ID override

No output schema declared.

No examples provided.

zuckerbot_update_portfolio ~136

Update the name, total daily budget, active status, or tier configuration of an existing audience portfolio. Changes to budget and tiers take effect on the next autonomous evaluation cycle. Use this to adjust a portfolio without relaunching all tiers.

NameTypeReqDescription
is_activebooleanEnable or disable the portfolio for autonomous evaluation
namestringNew portfolio name
portfolio_idstringyesAudience portfolio ID to update
tiersarrayUpdated tier configuration. Replaces the existing tiers array.
total_daily_budget_centsintegerNew total daily budget in cents (minimum 500)

No output schema declared.

No examples provided.

zuckerbot_upload_business_context ~125

Upload a text document (ad performance data, brand guidelines, customer data, sales data, or competitor analysis) so ZuckerBot can extract structured planning insights from it. Accepts raw text content — not binary files. Use this when the business has existing performance data or brand docs that should inform campaign strategy.

NameTypeReqDescription
business_idstringOptional business ID override
contentstringyesFile content as text
context_typestringOptional hint about the type of uploaded context
filenamestringyesName of the file or document

No output schema declared.

No examples provided.

zuckerbot_upload_creative ~139

Upload finished creative assets (images or videos) to an approved intelligence campaign. ZuckerBot queues the Meta upload and ad-creation jobs asynchronously, then polls until they complete or the polling window expires. Use this when you have your own creative assets ready.

NameTypeReqDescription
campaign_idstringyesIntelligence campaign ID
creativesarrayyesCreative assets to attach to the campaign
meta_access_tokenstringOptional Meta/Facebook access token override
meta_ad_account_idstringOptional Meta ad account ID override (format: act_XXXXX)
meta_page_idstringOptional Facebook Page ID override

No output schema declared.

No examples provided.